This briefing covers critical security developments from July 13-14, 2026. The period was marked by significant supply chain compromises, including OAuth abuse campaigns by ShinyHunters targeting SaaS applications and a backdoored Jscrambler npm package downloaded nearly 1,500 times. Law enforcement actions dominated threat actor disruptions, with U.S. sanctions against First VPN Service (1VPNS) used by ransomware groups, and coordinated EU-UK sanctions targeting Russian GRU cyber operations. Critical vulnerabilities emerged across multiple platforms, including 9Router API key exposure (CVSS 9.1), Spring Boot Admin SSRF (CVSS 8.6), and multiple authorization bypass flaws in OpenClaw and ChurchCRM. CISA disclosed a six-month credential leak incident involving AWS GovCloud keys published to GitHub, while Progress Software issued emergency shutdown guidance for ShareFile Storage Zone Controllers due to credible external threats. Ransomware groups continued aggressive campaigns with D1R claiming breaches of major technology firms Synopsys, ARM, and Bosch, though verification remains pending.
Multiple critical vulnerabilities require immediate attention, including authentication bypasses, SSRF flaws, and RCE vulnerabilities across enterprise platforms.
9Router through 0.4.41 exposes plaintext API keys for all connected AI providers via unauthenticated /api/usage/stats endpoint. CVSS 9.1 - attackers can retrieve credentials without authentication.
ChurchCRM before 7.4.0 allows authenticated administrators to achieve RCE by installing malicious plugin ZIP archives containing PHP webshells. CVSS 9.1 - PHP files explicitly allowed in upload validation.
Progress Software urgently instructing ShareFile Storage Zone Controller customers to immediately shut down servers due to credible external security threat. On-premises file-sharing infrastructure at immediate risk.
Spring Boot Admin Server before 4.1.2 allows unauthenticated attackers to register instances with attacker-controlled URLs without validation against private IP ranges. CVSS 8.6 - enables force browsing to metadata endpoints.
CISA warns attackers actively exploiting vulnerabilities in iCagenda and Balbooa Forms Joomla extensions to achieve remote code execution through arbitrary file uploads.
OpenClaw versions before 2026.6.9 contain numerous authorization bypass flaws allowing privilege escalation, policy circumvention, and unauthorized command execution. CVSS scores range from 7.1 to 8.8 across 15+ CVEs.
Cockpit CMS bucket storage API vulnerable to path traversal (CVE-2026-57856) and missing authorization checks (CVE-2026-57855). Authenticated attackers can access arbitrary files and execute privileged bucket operations. CVSS 8.8.
ColdFusion 2025.9 and 2023.20 affected by uncontrolled search path vulnerabilities (CVE-2026-48363, CVE-2026-48364) enabling arbitrary code execution. CVSS 8.2 - requires user interaction to open malicious file.
WordPress core affected by multiple vulnerabilities including SSRF (CVE-2026-57815, CVSS 7.5) and authorization issues (CVE-2026-57814, CVSS 7.1; CVE-2026-57407, CVSS 7.2).
Multiple malware campaigns identified including supply chain attacks, infostealers, and botnet activity targeting diverse platforms.
Jscrambler client-side security company disclosed threat actors published malicious version of its npm package containing infostealer malware. Downloaded approximately 1,500 times before detection. Supply chain attack targeting web security tools.
New macOS infostealer malware CrashStealer disguises itself as Apple's crash-reporting tool to steal credentials, keychain data, and cryptocurrency wallets from Mac users.
GigaWiper implant combines backdoor and wiper functionalities in modular framework, borrowing from various malware families. Allows threat actors to customize destructive attacks while minimizing operational overhead.
Proof-of-concept attack hides malicious AI instructions within PNG files, turning routine code reviews into vectors for secret theft. Prompt injection enables covert data exfiltration during AI-assisted development workflows.
Multiple Mirai botnet C2 URLs detected distributing ELF payloads for various architectures (ARM, MIPS, x86). Active distribution from wifihgu.duckdns.org and multiple IP addresses targeting IoT devices.
Ongoing ClearFake malware distribution via multiple domains serving Windows and macOS variants. HTTPS-hosted payloads targeting cross-platform victims with different payload hashes per operating system.
Multiple IoT-targeted Mozi botnet samples distributed from compromised hosts across Asia-Pacific region. 32-bit ARM and MIPS ELF binaries actively spreading via vulnerable devices.
Major law enforcement disruptions of cybercriminal infrastructure alongside ongoing APT campaigns targeting critical sectors.
U.S. Treasury sanctioned First VPN Service (1VPNS) and Ukrainian administrator for enabling ransomware gangs behind attacks on municipalities, hospitals, schools, and businesses. Separately sanctioned Belarusian for malware cryptor services.
First-ever coordinated EU-UK cyber sanctions package targeting Russian FSB and GRU military hackers. Sanctions imposed on dozens of individuals and entities responsible for cyberattacks and disinformation campaigns across Europe.
UK National Crime Agency charged five individuals following investigation into Russian Coms caller ID spoofing platform used for over 1.8 million scam calls targeting victims worldwide.
Microsoft Threat Intelligence identified activity with ShinyHunters tradecraft including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS platforms. Multi-vector attack campaign abusing OAuth mechanisms.
Nine-nation joint cybersecurity advisory warns Russian state hackers targeting vulnerable and misconfigured routers to infiltrate critical infrastructure networks. Persistent threat to SCADA and industrial control systems.
Notable security incidents and forensic investigations affecting organizations globally.
CISA issued postmortem on contractor data leak exposing dozens of internal credentials including AWS GovCloud keys in public GitHub repository for nearly six months. KrebsOnSecurity provided initial notification.
Nihon Kotsu, Japan's largest taxi operator, forced to shut down portions of infrastructure following cyberattack. Systems compromised requiring emergency response and partial service suspension.
German supermarket chain Lidl notified customers in Germany, Belgium, and Netherlands that personal information stolen in breach at third-party service provider. Supply chain attack affecting multiple European markets.
German textile company ZEGO Textilveredelungszentrum GmbH filing for insolvency proceedings as result of cyberattack in March 2026. Attack caused sufficient operational and financial damage to force bankruptcy protection.
Fourteen organizations added to ransomware leak sites with claims ranging from major technology firms to regional businesses across multiple sectors.
D1R ransomware group claims breaches of major technology companies Synopsys, ARM, and Bosch. Alleges access via cross-referenced leaked databases, downloading ARM center data despite 2FA restrictions and Bosch CAN module implementation worth $10,000. Claims require verification.
Akira ransomware group lists Transworld Signs (promotional/POP graphics producer) with 17GB data and Ironmark (marketing/printing services) with 190GB corporate data including employee information, client records, and financial documents.
DragonForce lists Northeast Rescue Systems (emergency/industrial safety equipment), Philippines-based Trans World Trading Company (materials/chemicals), Argentina law firm Nicholson y Cano Abogados, and food operator Degeremcia with stolen corporate data.
SpaceBears group claims Polish industrial engineering firm Techpol-System and Cameroon-based Turbosoft (IT systems/payroll solutions). Turbosoft breach exposes employee/client personal information and financial data from payroll, accounting, and HR systems.
SafePay ransomware group adds Connecticut-based Shuttle Meadow Country Club, one of New England's oldest private golf clubs founded in 1917. Member and operational data at risk.
Federal High Court in Abuja set July 21, 2026 arraignment date for Zenith Bank Plc and three other defendants over allegations of illegally accessing and disclosing confidential financial records of Makers Island Company Limited.
Significant policy developments including proposed social media age restrictions and major authentication framework changes.
Microsoft announces passkeys becoming default sign-in experience in Entra ID with introduction of new model for SMS and voice authentication. Major shift in enterprise authentication standards requiring organizational preparation.
European Commission President Ursula van der Leyen announces consensus on requiring minimum age of 13 for social media access. While implementation remains parental decision, EU leaders establishing regulatory framework for children's online safety.
New defensive tools and techniques for security practitioners including AI-driven scam engagement and hands-on training platforms.
Open-source AI-driven system adopts victim personas to engage with phishing attackers, enabling organizations and law enforcement to gather intelligence on cybercriminal operations. Automated honeypot approach for threat intelligence collection.
Varonis releases free hands-on Capture the Flag challenge teaching defenders how to investigate Entra ID attack techniques using realistic scenarios. Educational platform for learning cloud identity security investigation.
Organizations establishing specialized 'yellow teams' of engineers building both defensive and offensive AI tools to test potential of artificial intelligence for cybersecurity operations and threat modeling.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.